Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WhatsApp Attack Uses Fake Files to Deploy RMM Software

WhatsApp Attack Uses Fake Files to Deploy RMM Software

Posted on June 23, 2026 By CWS

In a recent cyber threat campaign, WhatsApp users are being targeted with malicious Visual Basic Script (VBScript) files disguised as legitimate documents. This operation is aimed at installing genuine Remote Monitoring and Management (RMM) software on victims’ systems, raising alarms in the cybersecurity community.

Global Targeting of WhatsApp Users

According to Kaspersky’s findings, this campaign affects users of WhatsApp Desktop and Web in various countries, including Malaysia, Brazil, India, and others. The highest number of victims is reported in Malaysia. The attackers use deceptive file names that appear to be business or financial documents to trick recipients into downloading and running the files.

Security expert Fareed Radzi has noted that the VBScript initiates a multi-step infection process that ends with the installation of RMM software, granting remote access to the attackers. The exact method of how the attackers gain control over WhatsApp accounts remains uncertain.

Deceptive Techniques and Obfuscation

The VBScript files are heavily obfuscated, camouflaged as harmless documents with names like “Financial Reports.vbs” or “Account Statement.vbs.” These files also appear in multiple languages, showcasing the global reach of the threat. Kaspersky highlights that the scripts contain metadata mimicking legitimate Microsoft components, with notes in Chinese relating to system integrity and update functionalities.

Execution of the VBScript is done through “WScript.exe,” which then retrieves additional components for subsequent attack stages. The infection process varies slightly depending on whether the victim uses WhatsApp Web or Desktop, with distinct methods of execution and file handling in each scenario.

Potential Threats and User Precautions

The ultimate goal of the VBScript is to download further scripts aimed at altering Windows User Account Control (UAC) settings and deploying a ZIP file with the ManageEngine RMM Central installation package. While the attackers remain unidentified, Kaspersky has found infrastructure connections to previous Gh0st RAT and ValleyRAT activities.

Users are advised to exercise caution when receiving unexpected documents through WhatsApp, even those seemingly from known contacts. It’s crucial to verify the authenticity of file types such as VBS, EXE, and others before opening them to avoid potential security risks.

As this threat continues to evolve, maintaining vigilance and adopting robust cybersecurity practices are essential for protecting sensitive information and systems from unauthorized access.

The Hacker News Tags:cyber threat, Cybersecurity, Kaspersky, Malware, Phishing, remote access, RMM software, social engineering, VBScript, WhatsApp

Post navigation

Previous Post: Xsolis Data Breach Impacts 1.4 Million People
Next Post: London Hydro Investigates Customer Data Breach

Related Posts

Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks The Hacker News
New Flaw in IDEs Like Visual Studio Code Lets Malicious Extensions Bypass Verified Status New Flaw in IDEs Like Visual Studio Code Lets Malicious Extensions Bypass Verified Status The Hacker News
Vercel’s v0 AI Tool Weaponized by Cybercriminals to Rapidly Create Fake Login Pages at Scale Vercel’s v0 AI Tool Weaponized by Cybercriminals to Rapidly Create Fake Login Pages at Scale The Hacker News
Cybersecurity Concerns Rise: Deceptive Extensions and Phishing Tactics Cybersecurity Concerns Rise: Deceptive Extensions and Phishing Tactics The Hacker News
The State of Trusted Open Source The State of Trusted Open Source The Hacker News
Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • In-Browser Data Inspection Revolutionizes Phishing Analysis
  • Dropping Elephant’s Deceptive New Cyber Tactics Unveiled
  • AWS Highlights Risks of Unmonitored Outbound Cloud Traffic
  • Massive Credential Theft Targets FortiGate Firewalls Worldwide
  • Global Call for Cybersecurity Grants by Internet Society

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • In-Browser Data Inspection Revolutionizes Phishing Analysis
  • Dropping Elephant’s Deceptive New Cyber Tactics Unveiled
  • AWS Highlights Risks of Unmonitored Outbound Cloud Traffic
  • Massive Credential Theft Targets FortiGate Firewalls Worldwide
  • Global Call for Cybersecurity Grants by Internet Society

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark